Bugzilla – Bug 1218941
VUL-0: CVE-2024-0646: kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination
Last modified: 2024-06-25 18:06:02 UTC
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-0646 https://bugzilla.redhat.com/show_bug.cgi?id=2253908 https://www.cve.org/CVERecord?id=CVE-2024-0646 https://access.redhat.com/security/cve/CVE-2024-0646 Patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c5a595000e267
Tracking as affected: -SLE15-SP6
Commit is now integrated into SLE15-SP6
All done, closing.